Global
International security developments, NATO, and geopolitical threats.
CENTCOM completes tenth consecutive night of strikes on Iran; Kuwait and Jordan intercept missiles as ceasefire proposal stalls
US Central Command completed a tenth consecutive night of strikes against Iran into 21 July, targeting command centres, maritime capabilities, missile and drone launch sites, and air-defence systems tied to attacks on commercial shipping in the Strait of Hormuz. The retaliation cycle continues to widen: Kuwait intercepted hostile missiles and drones after two earlier rounds of Iranian attacks, and Jordan downed three missiles launched from Iranian territory. The Pentagon confirmed three US service members killed over the weekend — two in Jordan, one in northern Iraq. Mediators have floated a ten-day ceasefire, but Washington has publicly downplayed the prospect of acceptance. For organisations with regional exposure the planning picture is unchanged but hardening: air corridors and overland routes across seven states are now subject to intermittent closure without notice, duty-of-care obligations extend to staff in states previously treated as safe rear areas, and any contingency plan that assumes a stable Gulf hub — Kuwait City, Amman, Manama — needs a validated alternative.
Russian strike kills at least ten on corn ship near Odesa — second fatal attack on a civilian cargo vessel in three days
A Russian strike on a Guinea-Bissau-flagged ship carrying corn near the port of Odesa killed at least ten people on 20 July, with a crew drawn from India and Syria. It is the second fatal strike on a civilian cargo vessel in the Black Sea corridor in three days, following the 19 July attack that killed five crew on a grain carrier. The pattern now reads as targeting rather than incident: civilian designation, third-country flags, and non-combatant crews are not preventing strikes on vessels in Ukrainian port approaches. For charterers, cargo owners and marine insurers, the operating assumptions that survived the earlier phases of the war — that grain-corridor traffic carries elevated but insurable risk — are being repriced in real time. Crewing agencies in India and the Philippines are already reviewing deployment consent for Black Sea voyages; organisations with cargo or personnel exposure in the corridor should treat crew-safety clauses, war-risk cover thresholds and abort criteria as live contractual questions this week.
Ukraine answers with 400-drone attack on Moscow region — oil depot, logistics sites and shadow-fleet tankers hit
Ukraine launched one of its largest drone operations of the war in the early hours of 20 July — around 400 drones against the Moscow region — striking an oil depot and logistics facilities and wounding ten people, with smoke visible over Podolsk south of the capital. President Zelenskyy additionally confirmed strikes on two shadow-fleet tankers and four cargo ships. Russia's overnight reply used two guided missiles and 94 strike drones against Ukraine. The professional takeaway sits beyond the front line: drone attacks at this scale against logistics and energy infrastructure deep inside a defended homeland are now an established capability, not an outlier. Security managers responsible for fuel storage, distribution hubs and port-adjacent estates anywhere in Europe should read this as the demonstration environment for tactics that migrate — perimeter assumptions built around ground intrusion do not answer a threat that arrives at altitude, and detection, reporting and shelter procedures for airborne incidents deserve a place in site standing instructions.
European Union
EU security directives, Europol threat assessments, and policy developments.
NATO warns of state-linked cyberattacks on Europe's civilian ports as alliance formally condemns Russian cyber campaign
NATO has warned that state-linked actors are conducting cyberattacks against Europe's civilian ports, exposing gaps in maritime digital defence, while the North Atlantic Council issued a formal condemnation of Russia's cyber operations against allies and Ukraine and the alliance's deputy secretary general called for imposing real costs on Russia and China for cyber and hybrid attacks. For port operators, terminal handlers and the logistics chains that depend on them — a category that includes a substantial share of Dutch industry — the warning formalises what incident data has shown for months: OT systems, berth-management platforms and gate-automation infrastructure are being probed by actors with state resources. The practical gap is rarely the firewall; it is the seam between IT security and physical operations. Organisations should verify that a cyber incident affecting access control, gate systems or cargo-release platforms triggers a physical-security response — manual gatekeeping, credential verification, controlled fallback procedures — rather than an improvised one.
SharePoint zero-day fallout continues: CISA remediation deadline passes as SharePoint 2016 and 2019 exit support
The exploitation wave against Microsoft SharePoint that began with July's record 622-CVE Patch Tuesday is entering its more dangerous second phase. CISA's remediation deadline for CVE-2026-58644 — the actively exploited deserialisation flaw allowing unauthenticated remote code execution — passed on 19 July, and incident responders report continued exploitation against unpatched estates. The structural problem is larger: SharePoint Server 2016 and 2019 reached end of extended support on the same day the patches shipped, meaning organisations still running those versions have received their final security update while two actively exploited vulnerability classes circulate. On-premises SharePoint typically holds exactly the material a hostile intelligence operation wants — contracts, board papers, M&A files, security documentation. Organisations that cannot migrate immediately should treat legacy SharePoint as a compromised-adjacent asset: segment it, restrict internet exposure, monitor for the published indicators, and assume documents stored there may already have been read.
The Netherlands
AIVD, NCTV, and domestic security developments relevant to Dutch operations.
Terror threat remains 'substantial', Dutch security services warn — Iran escalation raises attack likelihood in the Netherlands and Europe
Dutch security services are re-emphasising that the terrorist threat against the Netherlands remains at level four of five — 'substantial' — with the NCTV's half-yearly threat assessment warning that developments surrounding Iran increase the likelihood of an attack in the Netherlands and Europe. Jihadism remains the largest single threat, most plots are being disrupted early, and the assessment flags accelerating online radicalisation of minors and the normalisation of right-extremist ideology as growing concerns. With the US–Iran confrontation now in its second week, the Iran-linked warning carries more operational weight than when the assessment was drafted: organisations with visible international profiles, diplomatic adjacency, or Jewish and Israeli-linked communities in their vicinity should review their posture against the current picture. Practically that means revisiting access-control discipline at publicly accessible premises, briefing reception and guarding staff on hostile-reconnaissance indicators, and confirming escalation paths to police for suspicious-activity reports are current and tested.
Seven Dutch provinces pool cybersecurity into a joint Security Operations Center as EU deadline pressure mounts
Seven Dutch provinces — Drenthe, Flevoland, Friesland, Limburg, Overijssel, Utrecht and Zeeland — are establishing a shared Security Operations Center to monitor and defend their digital infrastructure jointly, a direct response to the obligations arriving with the EU's NIS2-derived rules. The move lands while the Netherlands itself faces possible legal action from the European Commission for failing to transpose the new cybersecurity law on time — a gap that leaves thousands of Dutch organisations formally in scope of European obligations without the national enforcement framework that defines them. For private organisations the provincial initiative is a useful signal of where compliance practice is heading: pooled detection capability, shared incident response, and explicit governance over who acts when systems are compromised. Organisations that fall under NIS2 categories — energy, transport, logistics, digital infrastructure, manufacturing — should not read the delayed Dutch law as delayed obligations: the directive's duty-of-care and incident-notification requirements are already the de facto standard that insurers, clients and auditors measure against.
Netherlands assigns amphibious task group to NATO's Allied Reaction Force; German-Dutch corps takes tactical command for Estonia and Latvia
The Netherlands has assigned an amphibious task group to the NATO Allied Reaction Force, the alliance's rapid-response formation held at readiness for a full year for immediate deployment across the treaty area, while 1 German-Netherlands Corps has taken over as the tactical NATO headquarters responsible for Estonia and Latvia. Alongside the Dutch contribution to the anti-ballistic-missile coalition reported last week, the assignments confirm the direction of Dutch defence policy: forward-committed, Baltic-facing, and structurally integrated with German command arrangements. The civilian-security consequence is capacity: sustained military commitments of this scale tighten the market for experienced security personnel, as defence, NATO installations and the protection of related infrastructure absorb cleared professionals. Organisations planning security staffing for the second half of 2026 — particularly for critical-infrastructure and defence-adjacent sites — should expect a competitive market for certified officers and build lead time into contracting rather than assuming spot availability.
Compiled from credible pro-EU, pro-NATO news sources. Mission Support does not publish operational specifics or unverified claims.
Ready to speak with a specialist?
We respond within one business day. Initial conversations are confidential and without obligation.
Request a Consultation